Arevipharma Privacy Statement

(as of July 11, 2018)

We care about the protection of your data

We are delighted about your interest in our company, our products and services and want you to feel save with regard to the protection of your personal data when visiting our website. Protecting your privacy is important to us and complying with the provisions pursuant to the General Data Protection Regulation (“GDPR”), the German Federal Data Protection Act (“BDSG”, as amended) and the German Telemedia Act (“TMG”) is a matter of course. By means of this privacy notice, we wish to inform you as to when we collect and how we use what kind of data. Within the scope of our continuous improvement process we always strive to implement all technical and organizational measures in order to ensure for all data protection requirements to be met both by us and the external service providers engaged by us.

Name and address of Controller

Controller pursuant to data protection regulations is:

Arevipharma GmbH
Meißner Straße 35
01445 Radebeul

Scope of personal data processing

We generally process our users’ personal data only if required in order to provide a functional website as well as our content and services. We generally process our users’ personal data only upon the user’s consent. This does not apply in cases where the prior obtaining of the user’s consent is not possible for factual reasons and a processing of data is permitted by statutory provisions.

Legal basis for the processing of personal data

If we obtain consent of a data subject for the processing of personal data, such consent is based on Art. 6 Sec. 1 lit. a GDPR. Any granted consent may be revoked at any time. This also applies to the revocation of declarations of consent declared to us prior to the GDPR’s applicability, i.e., prior to May 25, 2018. Any consent’s revocation has only future effect and does not affect the legality of data processed prior to the revocation.

The processing of personal data required for the performance of an agreement, to which the data subject is a party, is based on Art. 6 Sec. 1 lit. b GDPR. This also applies to the processing of data required for the performance of pre-contractual measures.

If the processing of personal data is required in order to meet a legal obligation (statutory provision) applicable to our company, such processing is based on Art. 6 Sec. 1 lit. c GDPR.

If the data subject’s or another individual’s vital interests should require the processing of personal data, this is based on Art. 6 Sec. 1 lit. d GDPR.

If the processing should be required in order to preserve our company’s or a third part’s legitimate interests and if the data subject’s interests or fundamental rights and freedoms should not prevail over such interests, the processing is based on Art. 6 Sec. 1 lit. f GDPR. Examples for such balancing of interests is advertising or market and opinion research unless you have objected to the use of your data, the assertion of legal claims, and the defense during legal disputes or the prevention and investigation of crimes.

Deletion of data and term of storage

The data subject’s personal data will be deleted or blocked as soon as the reason for storage has lapsed. Data may also be stored if such storing was provided for by European or national legislators in EU regulations, laws or other provisions applicable to the Controller. The data are also blocked or deleted if a storage period required by such regulation should expire unless a continued storage of the data should be required for contract conclusion or performance purposes.

Data subjects’ rights

You have the right:

to obtain, pursuant to Art. 15 GDPR, information about your personal data processed by us. You are in particular entitled to demand information as to the purposes of the processing, the categories of personal data concerned, the categories of recipients to whom the personal data have been or will be disclosed, the envisaged storage period, the existence of a right to rectification, deletion, restriction of processing or to object to such processing, the existence of a right to lodge a complaint, the source of your data to the extent they have not been collected by us, as well as to the existence of automated decision-making, including profiling, and meaningful information about their particularities;

to request, pursuant to Art. 16 GDPR, rectification of incorrect or completion of your personal data already stored by us;

to request, pursuant to Art. 17 GDPR, deletion of your personal data stored by us, unless their processing should be required in order to exercise the right to freedom of expression and information, to comply with a legal obligation, for reasons of public interest, or for the establishment, exercise or defense of legal claims;

to request, pursuant to Art. 18 GDPR, restriction of processing of your personal data, if you should contest the accuracy of the personal data, the processing should be unlawful and you oppose the data’s erasure, and if we no longer need the data but the data are required by you for the establishment, exercise or defense of legal claims or if you have objected to their processing pursuant to Art. 21 GDPR;

to receive, pursuant to Art. 20 GDPR, your personal data provided to us in a structured format or to demand transmission of the data to another controller;

to withdraw, pursuant to Art. 7 Sec. 3 GDPR, your consent granted to us at any time. Consequently, we are no longer allowed to continue with the processing of data based on such consent in future; and

to lodge a complaint with a supervisory authority pursuant to Art. 77 GDPR. For that purpose, you can generally refer to the supervisory authority responsible for your place of habitual residence, place of work or place of the alleged infringement.

Collection of general information

Personal Data
Personal data constitute information on your identity. This includes, for example, name, address, telephone number, and email address. In order to use our website it is not necessary to provide such data.

We process personal data received from our customers or other data subjects within the scope of our business relationship. We furthermore process – to the extent required for the provision of our services – personal data reliably collected from publicly available sources (e.g., commercial registers, registers of association, media, and internet).

When visiting our website, we collect, for statistical purposes, data submitted to us by your browser. This includes your browser type/version, your applied operating system, the previously visited website, your IP address and the time of the server request.

If you wish to contact us in person, for example, within the scope of an application procedure, for the delivery of information material or in order to respond to individual questions, we require your name, your address and further information, if applicable. If required, we will inform you accordingly. You provide such data to us on a voluntary basis and Arevipharma will process such data only in order to fulfill the respective purpose. You have the right to information on, correction, blocking and deletion of your personal data at any time, unless prevented by statutory provisions.

We shall neither sell to any third party nor otherwise market the data provided by you. Any disclosure of personal data to authorized state institutions and authorities will be made exclusively in accordance with applicable laws or if we are required to do so due to a court decision. Within our company, only the departments requiring the data in order to fulfill our contractual and legal obligations will get access to your data. Service providers and agents engaged by us can also receive your data for such purposes. Our employees and service providers engaged by us for the processing of data have been committed by us to confidentiality and compliance with the provisions pursuant to European General Data Protection Regulation (GDPR).

Such technical data are processed in anonymous form and for statistical purposes only in order to further optimize our online presence and to create an even more attractive website and in order to provide to prosecution authorities any information required for prosecution purposes in case of a cyber-attack. The data are stored on secured systems. We do not draw any conclusions as to individual persons.

Cookies

Our websites use so-called session cookies. They serve to make our range of services more user-friendly, effective and secure. Cookies are small text files received by your browser and stored in your computer. Session cookies are only stored until you log out of your browser. Naturally, you can also view our websites if your browser does not accept the use of cookies.

SSL encryption

In order to provide for a secure transmission of your data, we use state-of-the-art encryption methods (e.g., SSL) through HTTPS. All information and data transmitted by means of such secure methods are encrypted before they are sent to us.

Google Analytics

This website uses Google Analytics, a web analysis service of Google Inc. (“Google”). Google Analytics uses so-called “cookies”, text files stored on your computer which provide for an analysis of your use of the website. The information on your use of the website generated by the cookie is generally transmitted to and stored on one of Google’s servers in the US. If, however, the IP anonymization function is activated on this website, your IP address is shortened by Google within member states of the European Union or other contracting parties to the Agreement on the European Economic Area. Only in exceptional cases, the full IP address is transmitted to one of Google’s servers in the US and shortened there.

On behalf of this website’s operator, Google is going to use such information in order to analyze your use of the website, in order to compile reports on website activities and in order to provide to the website operator further services related with the use of the website and the internet.

The IP address transmitted by your browser within the scope of Google Analytics will not be merged by Google with other data. You can prevent storage of the cookies by a certain setting of your browser software; however, please note that in such case you might not be able to fully use all of this website’s functions.

Furthermore, you can prevent Google’s collection of data generated by the cookie and related with your use of the website (incl. your IP address) and the processing of such data by Google, by downloading and installing the browser plug-in available under the following link tools.google.com/dlpage/gaoptout

Children and teenagers

Persons under the age of 18 should not provide any personal data to Arevipharma GmbH without their parents’ or legal guardians’ consent. We do not request, collect and disclose to third parties personal data of children and teenagers.

Security

We have taken all technical and organizational measures in order to protect your personal data against loss, destruction, manipulation and unauthorized access. All our employees, persons involved in the processing of data and all service providers engaged by us for the processing of data have been committed to comply with the EU General Data Protection Regulation (GDPR), German Federal Data Protection Act (BDSG, as amended) and other data protection regulations as well as to a confidential handling of personal data.

In case of a collection and processing of personal data, the information is transmitted in encrypted form in order to prevent any misuse of data by third parties. Our security measures are permanently updated in accordance with technical developments.

Amendment of our privacy notice

We reserve the right to amend our security and data protection measures if required due to technical developments. In such case we are going to adjust our privacy notice accordingly. We therefore kindly ask you to please observe our privacy notice, as amended.

Links

If you use external links available on our websites, this privacy notice does not extend to the linked external websites. To the extent we provide links to external websites we assure that, at the date of the link’s embedding, we were not aware of any violations of applicable law on the linked websites. However, we have no influence on other providers’ compliance with data protection and security provisions. We therefore kindly request you to please inform yourself about the privacy notices provided on the other providers’ websites.
Right to information, right to object, questions, suggestions
You may obtain at any time information as to your personal data stored by Arevipharma. Please write to: Data Protection Officer
Helen Türke
Arevipharma GmbH
Meißner Straße 35
01445 Radebeul

or send an email to:
datenschutz@arevipharma.com

If you wish to withdraw your consent to our collection, processing and use of your personal data or in case you should have any questions, suggestions and complaints with regard to our privacy notice or our processing of your personal data, you may also directly address them to our Data Protection Officer.